87% of Firms Report AI Tools Accessing Unauthorized Data, Enforcement Lags

  • 87% of IT leaders reported AI tools accessing sensitive data beyond intended scope in the past year.
  • Only 19% of organizations can detect AI scope violations in real time.
  • 76% of employees admitted to bypassing AI usage approval processes.
  • 36% of IT leaders can trace unauthorized AI access back to a named human authorizer.
  • 47% of organizations lack enforcement at the moment of action in at least two major environments.

The findings highlight a critical gap in AI governance where near-universal policy adoption has failed to translate into effective enforcement. This trend underscores broader challenges in balancing AI productivity with security, particularly as employees increasingly bypass governance processes under time pressure. The report suggests that real-time authorization and continuous monitoring will become essential as AI integration deepens across enterprise environments.

Enforcement Gaps
How the disconnect between AI policy adoption and real-time enforcement will impact corporate security postures.
Employee Bypass
Whether organizations can curb the 76% of employees who bypass AI usage approvals when facing tight deadlines.
Detection Lag
The pace at which companies can reduce the 55% that take a full day or longer to detect AI scope violations.